Splunk Administration

Splunk Administration
Category Activity
ASW3382
I am revisiting splunk to see if it will meet our goals. Right now I am working on the initial index of our data gat...
by ASW3382 New Member in Getting Data In 05-24-2010
0 4
0
4
Jaci
Our indexer and all forwarders are running 4.1.2. Recently we developed a need to send events from our forwarders in...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-24-2010
1 3
1
3
Genti
What is the relationship between size of logs received by Splunk indexing servers versus indexing volume? On the load...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-24-2010
0 1
0
1
Jaci
I have a deployment server app with a single inputs.conf file. [tcp://localhost:9997] sourcetype = tcp-raw index = p...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-24-2010
1 2
1
2
johnpulley
I want to use Splunk to monitor the error output of a telephone switch. I can easily see the data by connecting to th...
by johnpulley New Member in Monitoring Splunk 05-24-2010
0 5
0
5
jeff
I have the following in inputs.conf: [udp://32004] host = custom_host connection_host = non...
by jeff Contributor in Getting Data In 05-22-2010
3 3
3
3
mctester
Hi, I have a development support question. We have an application that is integrated with splunk. We have a C++ p...
by mctester Communicator in Getting Data In 05-22-2010
2 1
2
1
dcroteau
we only want to save the log info for 2 weeks. I tried to set this up by modifying the frozen time, but it doesn’t s...
by dcroteau Splunk Employee Splunk Employee in Getting Data In 05-22-2010
1 3
1
3
maverick
Suppose I splunk a file and it is gzip'd on disk under the appropriate Splunk index directory. Then let's say I con...
by maverick Splunk Employee Splunk Employee in Getting Data In 05-22-2010
1 1
1
1
skibum
I am trying to use a host name in the stanza [udp://foo.514] but the name is not taking, on the same subject if I hav...
by skibum Engager in Security 05-22-2010
1 3
1
3
erydberg
I'm writing an app that I know will index loads of data and then do some calculations on changes from day to day. To ...
by erydberg Splunk Employee Splunk Employee in Knowledge Management 05-22-2010
2 2
2
2
Genti
Forwarding a question: "... attempting to setup a lookup table. Each time I save an automatic lookup it always retur...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-21-2010
0 1
0
1
apro
Hi, Been trying to backup and restore of Splunk indexer and the steps that I took to backup our splunk server is: - ...
by apro Path Finder in Monitoring Splunk 05-21-2010
1 2
1
2
Justin_Grant
If our app's inputs.conf uses an index other than "main" (e.g. a custom index for our app) does our app's setup UI (o...
by Justin_Grant Contributor in Getting Data In 05-21-2010
1 5
1
5
Jaci
Does a forwarder keep using the initial TCP connection to the indexing server, or does it close the connection after ...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-21-2010
2 1
2
1
return2health
Hi there. I'm new to splunk. Having a bit of trouble getting my head around it ( I know SQL well ) . I want to get...
by return2health Engager in Getting Data In 05-21-2010
1 2
1
2
Nicholas_Key
I am perplexed with what I'm experiencing right now. I have all the file inputs enabled for monitor but I'm not seei...
by Nicholas_Key Splunk Employee Splunk Employee in Getting Data In 05-21-2010
1 2
1
2
Jaci
I monitor a log file (access_log) that gets rolled every night at 1 am using a copy command "cp /dev/null access_toda...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-20-2010
1 3
1
3
JHill
Trying to configure a deployment server to support multiple organizations. I have created a directory structure withi...
by JHill Explorer in Deployment Architecture 05-20-2010
0 1
0
1
jwestberg
I am creating an app for Splunk 4.1 that has a scripted input that retrieves data from a database. At first run, it w...
by jwestberg Splunk Employee Splunk Employee in Getting Data In 05-20-2010
2 5
2
5
juank
I need to move my Splunk install from one server to another... What's is the procedure to backup the configuration/in...
by juank Engager in Installation 05-20-2010
1 3
1
3
Ledio_Ago
Let's say I have a distributed Splunk environment, n indexers, one search head and a forwarder load balancing input d...
by Ledio_Ago Splunk Employee Splunk Employee in Deployment Architecture 05-20-2010
3 2
3
2
phoenixsecure
Hi, I am collecting event logs thru WMI for Windows 2000 and 2003 servers, for 2003 everything seem ok but for 2000 ...
by phoenixsecure Engager in Getting Data In 05-20-2010
2 2
2
2
Chris_R_
How do keep splunk from removing syslog priority fields? They are removed once indexed into splunk.
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 05-19-2010
0 3
0
3
Yancy
Since I updated our server to 4.1.2 I'm seeing the following error with most searches. The lookup table 'sid_look...
by Yancy Path Finder in Getting Data In 05-19-2010
2 2
2
2
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...
Top Karma Authors